Why Zetna™
Least authority × cert-bound agents and machines × verification
= superintelligence that's safe to scale
Models will be moving faster than we can monitor them, so they have to be governed. Miss any one of these three and the whole thing is zero.
-
Least authority
An agent starts with no authority at all. A named person answers for each right it has, and anything consequential waits for that person's approval.
Delivered by the principles Closed by default, The approval means something and Every lever is bounded.
-
Cert-bound agents and machines
Each agent's key is created in hardware (a TPM chip or the Secure Enclave) and can't be copied off the machine; it signs every request. A replayed request is refused. Revoke the person, and every agent they issued stops.
Delivered by the principles Bound to a person, Stop anyone, act as no one and Detect, halt, report.
-
Verification
A signed receipt is made the moment an act happens or a credentialed caller is refused, and anyone can check it offline, without asking us. Witnesses co-sign the log, so a history rewritten later no longer matches what they saw.
Delivered by the principles Proven, not claimed, Never a middleman and Yours to take, free to leave.
Tokens, and keys tied to a person
Today an agent proves who it is with a token: a string that works like a password. Whoever holds the string is the agent. It leaks from config files and logs, and a poisoned prompt can make the agent read it out.
Everything that acts, people, agents and machines, holds a key it can't give away.
With Zetna, each agent's key is created in hardware (a TPM chip or the Secure Enclave) and can't be copied off the machine; it signs every request. Each signature is fresh, so a copied request or log gives an attacker nothing to reuse, and a replay is refused. The key is tied to a named person, and revoking that person stops their agents.
It's the BeyondCorp idea, which moved staff from shared secrets to keys on their own managed devices, applied to agents.
Agents get their credentials from their person's, so a service accepts an agent because its request is signed by a key that traces back to a named person. There's no API key to paste into a config, leak or rotate. One revoke cuts off the person and every agent they issued, everywhere the credential is accepted. Every service that accepts it makes it worth more to the next. One Credential
Agent identity products already register agents, tie each one to a human owner and approve each tool call, and that's real work. Where we differ is the credential: a key held in hardware signs every request, where a bearer token can be copied. The evidence is a receipt anyone can check without the vendor, and it's one credential across services and organisations.
Token
Cert-bound
What changes
- A copied request isn't enough, because every agent signs each request fresh with its own key, and a replay is refused.
- Every agent has someone who answers for it, because a named person issues its key. Revoke the person and their agents stop too.
- There's proof anyone can check without trusting us, because every act, and every refusal of a credentialed caller, is signed the moment it happens.
- A stop actually stops, because it's checked on every request, and the network admission check stops vouching for the agent too.
A neutral place to check
Operators can witness each other's logs, so nobody has to take one vendor's word for its own record.
Every Zetna install is witnessed automatically through Veriplex, the open verification federation. If you run a network, audit, build agents or compete with us, run a witness: write to hello@veriplex.org.